VulnSea

CWE-470

CVEs classified under CWE-470, newest first.

50 CVEsRSS

CVE-2026-17593High· 7.2
1mo ago

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configura…

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configura…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.77%via NVD
CVE-2026-64663Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…

▾ Sunlitstatamic · statamic/cmsEPSS 0.40%via NVD
CVE-2026-61536High· 7.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through impo…

▾ TwilightEPSS 0.51%via NVD
GHSA-pp9r-ppc4-25w4High· 8.8
2mo ago

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-53666Medium· 6.1
2mo ago

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

▾ Sunlitreact-router · react-routerEPSS 0.42%via GHSA
CVE-2026-46562Critical· 9.8
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed…

▾ Midnightspaceapplications · yamcsEPSS 0.98%via NVD
CVE-2026-44174None
2mo ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing attackers to include arbitrary model methods in their queries. Th…

▾ SunlitEPSS 0.49%via NVD
CVE-2026-58659High· 7.8
2mo ago

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters…

▾ TwilightRed Hat · Red Hat AI Inference ServerEPSS 0.63%via NVD
CVE-2026-14380High· 8.8
2mo ago

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the packa…

▾ Twilightperl · dbiEPSS 0.50%via NVD
CVE-2026-13772High· 7.5
2mo ago

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum li…

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum li…

▾ Twilightibm · websphere_extreme_scaleEPSS 0.51%via NVD
CVE-2026-49287High· 7.4
3mo ago

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

Statamic CMS's unsafe method invocation via collection sorting allows data destruction

▾ Twilightstatamic · statamic/cmsEPSS 0.46%via GHSA
CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-48517Medium
3mo ago

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments

▾ SunlitMessagePack · MessagePackEPSS 0.35%via GHSA
CVE-2026-57284Medium· 4.3
3mo ago

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

Jenkins Pipeline: Groovy Plugin vulnerable to unrestricted instantiation of types

▾ Sunlitjenkins · io.jenkins.plugins:pipeline-groovy-libEPSS 0.34%via GHSA
CVE-2026-44795High· 8.5
3mo ago

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types

▾ Twilightspinnaker · io.spinnaker.rosco:rosco-coreEPSS 1.0%via GHSA
CVE-2026-48817Medium· 5.3
3mo ago

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

▾ Sunlitstarlette · starletteEPSS 0.35%via OSV
CVE-2026-42027Critical· 9.8⚖ disputed
4mo ago

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loa…

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, String) method loa…

▾ Midnightapache · opennlpEPSS 1.3%via NVD
CVE-2018-25239Medium· 6.2
5mo ago

Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface

Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top ri…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-23923Medium· 5.3
6mo ago

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

▾ Sunlitzabbix · zabbixEPSS 0.27%via NVD
CVE-2021-21985Critical· 9.8CISA KEVPoC
5y ago

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to por…

▾ Hadalvmware · vcenter_serverEPSS 100%via NVD
CWE-470 vulnerabilities (CVEs) — page 2 · VulnSea